09/29/2026 | Press release | Distributed by Public on 09/29/2026 21:12
INDIANAPOLIS -- Indiana University Health Affiliated Covered Entity (IU Health) announced today that its vendor detected suspicious activity prompting the vendor to initiate their incident response protocols.
On August 4, 2026, IU Health learned that AME Group ("AME"), an IU Health IT vendor, may have been susceptible to a previously unknown software vulnerability associated with the information technology services AME was providing to an isolated IU Health legacy system. There is no evidence that IU Health's network or core systems were impacted. Upon notice, IU Health took immediate steps to verify the security of its systems, which remain unaffected. Additionally, IU Health undertook an independent review of AME's external vendor managed system to help determine what, if any, information may have been impacted. This review resulted in a determination of unauthorized access to limited imaging center information related to certain Southern Indiana patients' radiology files stored on the legacy system. There was no access to the IU Health electronic medical record system and patient care was not impacted.
The information involved varied by individual, but may have included name, date of birth, health plan member identification number, and other limited treatment information associated with the imaging center.
IU Health began notifying affected individuals on September 29, 2026, to make them aware of the situation and is providing dedicated call center support to answer any questions. We are committed to protecting personal information, and IU Health continues to implement security measures to prevent these activities from occurring in the future.
If you have any questions, please call toll-free at 888.752.8187, 9:00 a.m. to 9:00 p.m. Eastern Time, Monday-Friday (except major U.S. holidays).